Skip to content
Search AI Powered

Latest Stories

Google researcher links ransomware attack to North Korea

An security researcher with Google has found evidence suggesting that North Korean hackers may have carried out the "unprecedented" ransomware cyberattack that hit over 150 countries, including India.

Neel Mehta has published a code which a Russian security firm has termed as the "most significant clue to date", the BBC reported today.


The code, published on Twitter, is exclusive to North Korean hackers, researchers said.

Researchers have said that some of the code used in Friday's ransomware, known as WannaCry software, was nearly identical to the code used by the Lazarus Group, a group of North Korean hackers who used a similar version for the devastating hack of Sony Pictures Entertainment in 2014 and the last years hack of Bangladesh Central Bank.

Security experts are now cautiously linking the Lazarus Group to this latest attack after the discovery by Mehta.

Mehta has found similarities between code found within WannaCry and other tools believed to have been created by the Lazarus Group in the past, BBC reported.

Security expert Prof Alan Woodward said that time stamps within the original WannaCry code are set to UTC +9 - China's time zone - and the text demanding the ransom uses what reads like machine-translated English, but a Chinese segment apparently written by a native speaker, the report said.

"As you can see it is pretty thin and all circumstantial. However, it is worth further investigation," Woodward said.

"Neel Mehta's discovery is the most significant clue to date regarding the origins of WannaCry," said Russian security firm Kaspersky, but noted a lot more information is needed about earlier versions of WannaCry before any firm conclusion can be reached, it reported.

"We believe it is important that other researchers around the world investigate these similarities and attempt to discover more facts about the origin of WannaCry," it said.

Attributing cyberattacks can be notoriously difficult - often relying on consensus rather than confirmation, the report said.

North Korea has never admitted any involvement in the Sony Pictures hack - and while security researchers, and the US government, have confidence in the theory, neither can rule out the possibility of a false flag, it said.

Skilled hackers may have simply made it look like it had origins in North Korea by using similar techniques.

In the case of WannaCry, it is possible that hackers simply copied code from earlier attacks by the Lazarus Group.

"There's a lot of ifs in there. It wouldn't stand up in court as it is. But its worth looking deeper, being conscious of confirmation bias now that North Korea has been identified as a possibility," Woodward said.

Its the strongest theory yet as to the origin of WannaCry, but there are also details that arguably point away from it being the work of North Korea.

First, China was among the countries worst hit, and not accidentally - the hackers made sure there was a version of the ransom note written in Chinese. It seems unlikely North Korea would want to antagonise its strongest ally. Russia too was badly affected, the report said.

Second, North Korean cyber-attacks have typically been far more targeted, often with a political goal in mind.

In the case of Sony Pictures, hackers sought to prevent the release of The Interview, a film that mocked North Korean leader Kim Jong-Un. WannaCry, in contrast, was wildly indiscriminate - it would infect anything and everything it could, the report said.

Finally, if the plan was simply to make money, its been pretty unsuccessful on that front too - only around $60,000 has been paid in ransoms, according to analysis of Bitcoin accounts being used by the criminals.

With more than 200,000 machines infected, its a terrible return, the report said.

On Friday, Europol Director Rob Wainwright said: "The global reach is unprecedented. The latest count is over 200,000 victims in at least 150 countries and those victims many of those will be businesses including large corporations".

The most disruptive attacks were reported in the UK, where hospitals and clinics were forced to turn away patients after losing access to computers.

More For You

Starmer home

Police officers stand outside Starmer's private home, after it was damaged by fire in a suspected arson attack in north London, on May 13.

Reuters

Police arrest 21-year-old over fire at Starmer’s private residence

POLICE have arrested a 21-year-old man on suspicion of arson after fires were reported at three locations, including prime minister Keir Starmer’s private home in north London.

Officers were called in the early hours of Monday to a fire at a property in Kentish Town, which Starmer represents in parliament. No injuries were reported, but the entrance of the property was damaged.

Keep ReadingShow less
David-Lammy-Getty

Foreign secretary David Lammy said he hoped the ceasefire would be sustained and called for dialogue between the two sides. (Photo: Getty Images)

Getty Images

David Lammy urges India, Pakistan to sustain ceasefire

The UK on Saturday (10) welcomed the ceasefire agreedbetween India and Pakistan and urged both countries to continue steps towards de-escalation.

Foreign secretary David Lammy said he hoped the ceasefire would be sustained and called for dialogue between the two sides.

Keep ReadingShow less
Modi  speech

'If another terrorist attack against India is carried out, a strong response will be given,' Modi said.

Reuters

Modi warns of strong response to any future terrorist attack

PRIME MINISTER Narendra Modi on Monday said India would respond strongly to any future terrorist attack and would not tolerate "nuclear blackmail" in case of further conflict with Pakistan.

His remarks came after a weekend ceasefire appeared to be holding following four days of heavy fighting between the two sides. US president Donald Trump, who said he brokered the ceasefire, claimed on Monday that US intervention had prevented a "bad nuclear war".

Keep ReadingShow less
UK legal immigration

Among those who favoured reductions, 49 per cent prioritised reducing irregular arrivals such as small boat crossings, while only 4 per cent wanted fewer work or student visas.

iStock

Most Britons back immigration for work and study, new poll finds

A MAJORITY of people in Britain support immigration for work and study, according to a new survey published on May 11, ahead of the government's expected Immigration White Paper.

The poll, conducted by Focaldata for British Future, found that most respondents would not reduce immigration for doctors (77 per cent), care home workers (71 per cent), engineers (65 per cent), fruit pickers (70 per cent), catering staff (63 per cent) or lorry drivers (63 per cent). Two-thirds (65 per cent) also said they would not reduce the number of international students.

Keep ReadingShow less
Starmer-speech-Reuters

Although he did not give a specific target, Starmer said migration would fall sharply under his government’s new plan. (Photo: Reuters)

Reuters

Starmer pledges sharp fall in net migration by 2029

PRIME MINISTER Keir Starmer on Monday said net migration to Britain would drop significantly by the end of this parliament in 2029, promising greater control to support social cohesion and boost local workforce investment.

Speaking at a press conference in Downing Street, Starmer said countries need rules to define rights, responsibilities and obligations, and warned that without them, Britain risked "becoming an island of strangers".

Keep ReadingShow less